Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

Sometimes security breaches and hacking attacks come from the most unlikely of sources, even going so far as to utilize trusted applications to infect an endpoint or network. This is the case with a new phishing attack which uses the Calculator application that comes built-in with Windows in a very creative way. This is just one example of how hackers have been forced to innovate to combat the increasingly secure systems which businesses and users rely on today, and it should be a testament as to why you can never be too careful.

What is the Threat?

A security researcher who goes by ProxyLife on Twitter has reportedly discovered that there are several strains of malware and phishing attacks utilizing an outdated version of Microsoft’s Calculator application to find their way onto your network and launch their attacks—specifically the Windows 7 version of Calculator. The way that it works is that a cybercriminal tricks the user into downloading an ISO disc image which is disguised as a PDF or other similar file. This ISO contains a shortcut to an opened version of the Calculator application.

The Windows 7 Calculator can use what are called Dynamic Link Libraries in the same folder rather than defaulting to Windows’ system default libraries. The Calculator then runs the library, which is infected with malware. Later versions of Calculator do not have this capability, hence why an older version is necessary. Since Windows thinks that Calculator is a legitimate application, opening it in this way doesn’t set off any red flags within the system.

Should You be Worried?

At the end of the day, this is largely an obscure threat that sees hackers using the tools at their disposal in creative and different ways. It is not yet known if Microsoft has issued an update to Defender to put a stop to these types of attacks, but the long and short of it is that you probably won’t encounter this specific threat, as long as you are using proper security practices while browsing the Internet or checking your email.

Still, the idea that threats can use trusted and known applications in this way can make things a bit of a hassle for your IT team. These types of attacks might bypass the defenses built into your operating systems, but they can be caught if you are proactively monitoring your infrastructure for abnormalities. These abnormalities can then be contained, isolated, and eliminated. Of course, the problem here is that you likely wouldn’t find this type of threat if you weren’t actively looking for it—which is where we come in.

Proactively Monitor Your Network with Our Services

We know that it can be a challenge to keep your network safe. That’s why we make it easy with our remote monitoring services. Combined with comprehensive security solutions like a firewall, antivirus, spam blocker, and content filter, you’ll find that your network has never been safer. To learn more about what we can do for your business, contact us today at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Friday, 25 April 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud User Tips Network Security Internet Hardware Efficiency IT Support Malware Privacy Google Email Phishing Workplace Tips Computer IT Services Users Collaboration Hosted Solutions Mobile Device Ransomware Quick Tips Workplace Strategy Microsoft Small Business Cybersecurity Passwords Data Backup Communication Smartphone Backup Saving Money Android VoIP Business Management Smartphones Managed Service Mobile Devices communications Upgrade Disaster Recovery Data Recovery Browser Social Media Managed IT Services Microsoft Office Windows Tech Term Network Remote Internet of Things Current Events Productivity Automation Artificial Intelligence Facebook Cloud Computing Covid-19 Gadgets Server Managed Service Provider AI Miscellaneous Remote Work Outsourced IT Information Holiday Employee/Employer Relationship Spam Encryption Windows 10 Office Compliance Training Business Continuity Data Management Government Wi-Fi Business Technology Bandwidth Windows 10 Blockchain Virtualization Apps Two-factor Authentication Mobile Office Data Security Employer-Employee Relationship Managed Services Voice over Internet Protocol Chrome Mobile Device Management Budget Networking Gmail Apple App BYOD Vendor Computing Access Control Information Technology Hacker Tip of the week Conferencing Avoiding Downtime Office 365 IT Support Marketing How To BDR WiFi Applications Operating System Health Help Desk Risk Management Computers Retail Analytics Website Office Tips Healthcare Augmented Reality Managed IT Services Storage Password Bring Your Own Device Big Data HIPAA Router Virtual Private Network Printer Cybercrime Windows 11 Paperless Office Infrastructure Customer Service Monitoring 2FA Excel Document Management Remote Workers Telephone Scam Data loss Firewall Cooperation Free Resource Project Management Windows 7 Patch Management Save Money Microsoft 365 The Internet of Things Remote Monitoring End of Support Vulnerability Vendor Management Solutions Social Going Green Physical Security Display Content Filtering Computer Repair Mobile Security Processor Customer Relationship Management YouTube Holidays Cryptocurrency Data Storage Smart Technology Supply Chain Hacking Presentation Video Conferencing Machine Learning Managed Services Provider Virtual Machines Professional Services Saving Time Virtual Desktop LiFi Wireless Technology Data storage Managed IT Service Maintenance Outlook Downloads Antivirus iPhone Money Word Licensing Humor Vulnerabilities Entertainment Data Privacy Sports Mouse Images 101 Robot Mobility Safety Telephone System Multi-Factor Authentication Administration Cost Management IT Management VPN Employees Meetings Integration Settings Wireless Printing User Tip Modem Hosted Solution Database Surveillance Virtual Assistant Outsource IT Typing Network Management Tech Support IT Technicians Virtual Machine Environment Media Monitors Cyber Monday Medical IT Proxy Server Reviews Cookies Competition Tactics Development Knowledge Hotspot Transportation Small Businesses Google Drive Websites Mirgation Hypervisor Displays 5G PowerPoint Shopping Nanotechnology Optimization SharePoint Unified Communications Addiction Experience Electronic Medical Records Language Employer/Employee Relationships Outsourcing Google Docs Bitcoin Management PCI DSS Running Cable User Chatbots Navigation Screen Reader Writing Distributed Denial of Service Workplace Google Wallet Lenovo Gig Economy Service Level Agreement Internet Service Provider Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Evernote Paperless Windows 8 IP Address Server Management Regulations Compliance Laptop Private Cloud Identity Identity Theft Smart Tech Memes Co-managed IT Drones Superfish Bookmark Download Net Neutrality Twitter Alerts SQL Server Technology Care Business Communications Financial Data Halloween Recovery Error History Hard Drives Connectivity IT Social Engineering Break Fix Scams Browsers Smartwatch Domains Upload Procurement Remote Computing Azure Hybrid Work Multi-Factor Security Tech Human Resources Hacks Social Network Telework Scary Stories Cyber security Refrigeration Tablet IoT Communitications Fun Dark Web Cables CES Deep Learning Public Speaking Trends Supply Chain Management Alert Dark Data Google Calendar Term Google Apps Lithium-ion battery Managed IT Customer Resource management FinTech File Sharing Regulations Star Wars IT Assessment Entrepreneur How To Microsoft Excel IT Maintenance Data Analysis Education Gamification Flexibility Notifications Staff Value Business Intelligence Legislation Shortcuts Mobile Computing Organization Travel Social Networking Undo Google Maps Smart Devices Search Ransmoware Techology Fileless Malware Digital Security Cameras Best Practice Content Remote Working Wearable Technology Memory Vendors Comparison Google Play Be Proactive Health IT Buisness Unified Threat Management Motherboard Data Breach IT solutions Assessment Electronic Health Records Permissions Workforce Legal Unified Threat Management Directions Videos Business Growth Wasting Time Threats Network Congestion Specifications Security Cameras Workplace Strategies Application Trend Micro Internet Exlporer Software as a Service Cortana Fraud Meta User Error Microchip Alt Codes IBM Username Managing Costs Amazon Black Friday SSID Downtime Point of Sale eCommerce

Blog Archive